CSIDB logo
Threat actor

APT30

Attribution profile

Type
Nation State
Location
China
Known incidents
3 incidents
First seen
2020-01-03
Last seen
2022-07-19
Updated
2026-08-03 00:52
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

APT30 is an advanced persistent threat group that is publicly tracked under the alias APT30. Open‑source reporting associates the group with China, describing it as a Chinese state‑backed actor. The group’s affiliation with the Chinese state is indicated by attributions that label it among Chinese state‑linked APT groups operating from within Chinese territory. No alternative aliases for APT30 are documented in the provided sources. Its location is assessed to be China based on the state‑backed characterization.

In July 2022 Belgian authorities publicly attributed cyber intrusions against the Federal Public Service Interior and Defence ministries to a set of Chinese state‑backed APT groups, explicitly naming APT30 alongside APT27, APT31 and the Gallium/Softcell/UNC2814 cluster. Two separate Belgian statements, issued on 1 July 2022 and 19 July 2022, described the same activity targeting those ministries. The Belgian government stated that the activity compromised national sovereignty, democratic processes, security infrastructure and societal stability. It characterized the operations as cyberespionage aimed at gathering sensitive governmental information. No public source attributes financial gain or disruptive intent to APT30 in these incidents; the described impact aligns with intelligence‑collection objectives. Belgian officials urged China to adhere to international norms and noted that Chinese officials denied involvement while Belgium maintained its attribution.

The Belgian intrusion represents the most detailed publicly reported operation linked to APT30 to date, illustrating the group’s focus on high‑value government targets in Europe. While the reporting confirms the victim sectors and the strategic nature of the activity, it does not disclose specific malware families, initial‑access vectors, or tooling styles employed by APT30 in this campaign. Consequently, any description of the group’s technical tactics remains undocumented in the available open‑source material. No public reporting ties APT30 to financially motivated crime or to disruptive attacks unrelated to espionage. The available information therefore defines APT30 as a Chinese state‑backed espionage actor whose known activity centers on governmental targets.

Incidents

Attributed incidents are available to members.

3 incidents
CSIDB